Engineering and repository owners

GitHub Repository Guard for Enterprise AI Changes

Pilot AI code controls in report-only mode, review OIDC-bound decisions and require the GitHub check before merge when repository owners approve enforcement.

Choose your rollout path

Team uses organization billing and Stripe Checkout. Enterprise starts with a rollout call to agree the deployment scope.

Install my guardrail

Protect the change that reaches GitHub

A developer hook and a repository check cover different points. GitHub Repository Guard evaluates proposed repository changes against passport and policy context. The hosted path uses GitHub OIDC to bind the workflow to repository identity without a broad APort API key in CI secrets.

Review findings before requiring the check

Start with report-only visibility on a pilot repository. Inspect changed-file evidence, structural findings and the decision reference with the repository owner. Incomplete evidence is a review condition, not proof that the change is safe.

Report-only does not prevent merge. Configure enforcement and the required status check through your repository rules after testing a permitted change and a prohibited fixture. Keep human code review and existing CI checks.

Make repository rollout a team decision

Record which branches, workflow events and repositories the check covers. Name the owner who can change protected paths and the person who approves exceptions. GitHub report-only and blocking enforcement do not require a paid plan. Team adds organization audit, shared controls and setup support; Enterprise supports a wider rollout plan.

Prepare a reviewed setup

shell
npx @aporthq/aport-agent-guardrails github

Review the configuration and follow the framework verification guide before expanding the pilot.

Product and implementation sources

Choose your rollout path

Team uses organization billing and Stripe Checkout. Enterprise starts with a rollout call to agree the deployment scope.

Install my guardrail